Fetching from the wire…
Agents2026-08-06 · source-backed
arXiv 2608.04192 separates file secrecy from functional secrecy: even with perfect protection against prompt-injection file dumps, a user can rebuild what the files do. It forms an interface hypothesis from the skill's public description, issues benign structured probes, synthesizes an executable replica, then repairs it through differential validation against the victim. Exact or partial recovery on held-out inputs across 30 skills. Vaguer descriptions offered limited protection; the defense that works is rate-limiting cumulative information leakage from legitimate use.
Each link below shares sources, entities, or timing with this story.
A measurement paper published August 28 ran one adaptive adversary against a seven-layer stack and found failure correlation positive in all fifteen measurable pairs, phi between 0.30 and 0.75, with the joint residual exceeding the multiplicative prediction by up to 0.172. The...
Recuris (arXiv 2608.24876) keeps a Working Memory tracking current task progress separate from an Experiential Memory of learned skills, so skill selection indexes against what the task needs now rather than the whole history. It improves 35 of 37 model-benchmark pairs, gains...
The attack needs no instruction, trigger, or retriever optimization, just plainly worded false assertions generated in one pass against a LongMemEval corpus. A four-stage screening pipeline that reaches 0.832 recall on indirect prompt injection rejected none of the poisoned me...
Models navigate to the correct file for 92%+ of required deletions but cut the exact target line only 52% of the time, and 29% of passing patches wrap dead code in a conditional instead of removing it. Grep the diff for newly added if guards around code the task said to delete...
The trajectory-mining pipeline that segments, clusters, and trains a skill-aware policy produced clean skill clusters but only +1.95 points on one benchmark and negligible gains on another (arXiv:2606.20363). A useful negative signal against the hype: generating skills from in...
Poisoned entries in persistent memory force unintended tool selection during retrieval — even against explicit user instructions. Unlike prompt injection targeting input, MCFA targets the memory store, making it persistent and harder to detect. If your agent has long-term memo...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.